Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-17100

CVE-2026-17100: Power Systems Firmware RCE Vulnerability

CVE-2026-17100 is a remote code execution vulnerability in Power Systems Firmware affecting multiple versions. Attackers with service-level BMC/FSP access can execute arbitrary code in host firmware runtime. This article covers technical details, affected versions, impact, and mitigation strategies.

Updated:

CVE-2026-17100 Overview

CVE-2026-17100 affects IBM Power Systems Firmware across multiple release trains, including FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1, and OP940.00 through OP940.81. The flaw resides in the service processor mailbox interface used by the Baseboard Management Controller (BMC) and Flexible Service Processor (FSP). An authenticated attacker with service-level access can execute arbitrary code in the host firmware runtime, taking full control of the managed system. The weakness maps to an out-of-bounds write [CWE-787].

Critical Impact

Arbitrary code execution in host firmware runtime grants full control of the managed system, breaching confidentiality, integrity, and availability boundaries.

Affected Products

  • IBM Power Systems Firmware FW1120.00, FW1110.00FW1110.30, FW1060.00FW1060.80
  • IBM Power Systems Firmware FW950.00FW950.H2
  • IBM OpenPOWER Firmware OP940.00OP940.a1 and OP940.00OP940.81

Discovery Timeline

  • 2026-08-19 - CVE-2026-17100 published to NVD
  • 2026-08-20 - Last updated in NVD database

Technical Details for CVE-2026-17100

Vulnerability Analysis

The vulnerability exists in the service processor mailbox interface, the communication channel that allows the BMC/FSP to exchange commands and data with host firmware. An out-of-bounds write condition in the mailbox message handling path lets an attacker corrupt memory structures used by the host firmware runtime. Successful exploitation yields arbitrary code execution below the operating system boundary, breaking any trust anchored in the host firmware.

Because the attack crosses the security boundary between the service processor and the managed system, the scope of impact changes. A compromise of the BMC/FSP escalates into full control of the workloads running on Power hardware, including LPARs and hypervisor components.

Root Cause

The root cause is improper bounds validation on data received through the mailbox interface [CWE-787]. Message fields that should be constrained by size or type checks are written into firmware memory without adequate validation, allowing an attacker to place attacker-controlled bytes into unintended locations.

Attack Vector

Exploitation requires local, authenticated access at service-level privilege on the BMC or FSP. No user interaction is required. An attacker sends crafted mailbox messages from the service processor context to trigger the out-of-bounds write, then pivots into host firmware execution. See the IBM Support Page for vendor-supplied technical details.

No public proof-of-concept exploit is available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

Detection Methods for CVE-2026-17100

Indicators of Compromise

  • Unexpected service-level authentications to the BMC/FSP, especially from non-administrative sources or outside change windows.
  • Firmware integrity attestation failures or unexplained changes to host firmware version strings.
  • Anomalous mailbox command sequences or malformed message lengths observed in service processor logs.

Detection Strategies

  • Correlate BMC/FSP authentication events with change management records to identify unauthorized service-level sessions.
  • Enable and forward FSP/BMC audit logs to a centralized SIEM for retention and behavioral analysis.
  • Verify running firmware hashes against IBM-published values after any maintenance window.

Monitoring Recommendations

  • Restrict management network access to the BMC/FSP and monitor all inbound connections to management interfaces.
  • Alert on creation, modification, or privilege changes to service-level accounts on the service processor.
  • Continuously ingest firmware and management-plane telemetry into a data lake such as the SentinelOne Singularity Data Lake for long-horizon correlation across host and management events.

How to Mitigate CVE-2026-17100

Immediate Actions Required

  • Apply the fixed firmware levels published by IBM for each affected train as documented in the IBM Support Page.
  • Rotate all BMC/FSP service-level credentials and remove any unused service accounts.
  • Isolate management interfaces to a dedicated, access-controlled network segment.

Patch Information

IBM has released firmware updates addressing CVE-2026-17100 across the affected FW1120, FW1110, FW1060, FW950, and OP940 streams. Consult the IBM Support Page for the exact fixed levels applicable to each system model and firmware train.

Workarounds

  • Enforce strict network segmentation so the BMC/FSP management plane is unreachable from general-purpose or user-facing networks.
  • Limit service-level account membership to a minimal, audited set of administrators and require multi-factor authentication where supported.
  • Disable unused management protocols and interfaces on the service processor until patched firmware is deployed.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.